Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
uYtea.arm.elf

Overview

General Information

Sample name:uYtea.arm.elf
Analysis ID:1586057
MD5:2a803a7b7c48b7530c6a53c6dfe718a1
SHA1:dd3a35733efa7175deda0dba429ed6be44254926
SHA256:dc9049c50bf6f72a3fb1d6c39f2e3880a05c6f2335b64fd69ef635c541ed2d56
Tags:user-elfdigest
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Creates hidden files and/or directories
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Sample listens on a socket
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1586057
Start date and time:2025-01-08 17:06:02 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 21s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:uYtea.arm.elf
Detection:MAL
Classification:mal64.linELF@0/0@0/0
  • VT rate limit hit for: uYtea.arm.elf
Command:/tmp/uYtea.arm.elf
PID:5511
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:
connecterror
Standard Error:
  • system is lnxubuntu20
  • uYtea.arm.elf (PID: 5511, Parent: 5429, MD5: 5ebfcae4fe2471fcc5695c2394773ff1) Arguments: /tmp/uYtea.arm.elf
  • cleanup
SourceRuleDescriptionAuthorStrings
uYtea.arm.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xc4b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc4c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc4dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc4f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc504:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc518:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc52c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc540:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc554:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc568:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc57c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc590:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc5a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc5b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc5cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc5e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc5f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc608:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc61c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc630:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc644:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
SourceRuleDescriptionAuthorStrings
5511.1.00007f95a4017000.00007f95a4026000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xc4b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc4c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc4dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc4f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc504:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc518:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc52c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc540:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc554:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc568:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc57c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc590:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc5a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc5b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc5cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc5e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc5f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc608:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc61c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc630:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc644:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
5515.1.00007f95a4017000.00007f95a4026000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xc4b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc4c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc4dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc4f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc504:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc518:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc52c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc540:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc554:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc568:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc57c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc590:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc5a4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc5b8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc5cc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc5e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc5f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc608:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc61c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc630:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xc644:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: uYtea.arm.elf PID: 5511Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0xf085:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf099:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf0ad:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf0c1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf0d5:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf0e9:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf0fd:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf111:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf125:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf139:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf14d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf161:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf175:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf189:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf19d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf1b1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf1c5:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf1d9:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf1ed:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf201:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0xf215:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
Process Memory Space: uYtea.arm.elf PID: 5515Linux_Trojan_Gafgyt_28a2fe0cunknownunknown
  • 0x3eb1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3ec5:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3ed9:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3eed:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f01:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f15:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f29:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f3d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f51:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f65:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f79:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3f8d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3fa1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3fb5:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3fc9:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3fdd:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x3ff1:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4005:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4019:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x402d:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
  • 0x4041:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: uYtea.arm.elfAvira: detected
Source: uYtea.arm.elfReversingLabs: Detection: 65%
Source: global trafficTCP traffic: 192.168.2.15:35654 -> 141.98.10.115:1302
Source: /tmp/uYtea.arm.elf (PID: 5511)Socket: 127.0.0.1:9473Jump to behavior

System Summary

barindex
Source: uYtea.arm.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5511.1.00007f95a4017000.00007f95a4026000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: 5515.1.00007f95a4017000.00007f95a4026000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: uYtea.arm.elf PID: 5511, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: Process Memory Space: uYtea.arm.elf PID: 5515, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
Source: ELF static info symbol of initial sample.symtab present: no
Source: uYtea.arm.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5511.1.00007f95a4017000.00007f95a4026000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: 5515.1.00007f95a4017000.00007f95a4026000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: uYtea.arm.elf PID: 5511, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: Process Memory Space: uYtea.arm.elf PID: 5515, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
Source: classification engineClassification label: mal64.linELF@0/0@0/0
Source: /tmp/uYtea.arm.elf (PID: 5513)Directory: /tmp/.Jump to behavior
Source: /tmp/uYtea.arm.elf (PID: 5513)Directory: /tmp/..Jump to behavior
Source: /tmp/uYtea.arm.elf (PID: 5511)Queries kernel information via 'uname': Jump to behavior
Source: uYtea.arm.elf, 5511.1.000055971abb8000.000055971ace6000.rw-.sdmp, uYtea.arm.elf, 5515.1.000055971abb8000.000055971ace6000.rw-.sdmpBinary or memory string: U!/etc/qemu-binfmt/arm
Source: uYtea.arm.elf, 5511.1.000055971abb8000.000055971ace6000.rw-.sdmp, uYtea.arm.elf, 5515.1.000055971abb8000.000055971ace6000.rw-.sdmpBinary or memory string: /etc/qemu-binfmt/arm
Source: uYtea.arm.elf, 5511.1.00007fff0889e000.00007fff088bf000.rw-.sdmp, uYtea.arm.elf, 5515.1.00007fff0889e000.00007fff088bf000.rw-.sdmpBinary or memory string: /usr/bin/qemu-arm
Source: uYtea.arm.elf, 5511.1.00007fff0889e000.00007fff088bf000.rw-.sdmp, uYtea.arm.elf, 5515.1.00007fff0889e000.00007fff088bf000.rw-.sdmpBinary or memory string: x86_64/usr/bin/qemu-arm/tmp/uYtea.arm.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/uYtea.arm.elf
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
Hidden Files and Directories
OS Credential Dumping11
Security Software Discovery
Remote ServicesData from Local System1
Non-Standard Port
Exfiltration Over Other Network MediumAbuse Accessibility Features
No configs have been found
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Number of created Files
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
uYtea.arm.elf66%ReversingLabsLinux.Trojan.Mirai
uYtea.arm.elf100%AviraEXP/ELF.Mirai.Z.D
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs
IPDomainCountryFlagASNASN NameMalicious
141.98.10.115
unknownLithuania
209605HOSTBALTICLTfalse
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
141.98.10.115uYtea.mips.elfGet hashmaliciousUnknownBrowse
    uYtea.mpsl.elfGet hashmaliciousUnknownBrowse
      uYtea.arm7.elfGet hashmaliciousMiraiBrowse
        No context
        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
        HOSTBALTICLTuYtea.mips.elfGet hashmaliciousUnknownBrowse
        • 141.98.10.115
        uYtea.mpsl.elfGet hashmaliciousUnknownBrowse
        • 141.98.10.115
        uYtea.arm7.elfGet hashmaliciousMiraiBrowse
        • 141.98.10.115
        Scan12112024,pdf.vbsGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
        • 141.98.10.88
        Scan12112024,pdf.vbsGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
        • 141.98.10.88
        Scan112024.vbsGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
        • 141.98.10.88
        173127133603e75602cf90c03b229cc07ec4f5c026cad2909c809b767b293bf800a0e9ade9674.dat-decoded.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
        • 141.98.10.88
        ConfirmaciXnXdeXfacturaXPedidoXadicional.docGet hashmaliciousUnknownBrowse
        • 141.98.10.88
        DOC11042024.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
        • 141.98.10.40
        Contract #U2116 KB #U2013 08152024 - 1.pif.exeGet hashmaliciousRedLineBrowse
        • 141.98.10.33
        No context
        No context
        No created / dropped files found
        File type:ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
        Entropy (8bit):6.15481879326701
        TrID:
        • ELF Executable and Linkable format (generic) (4004/1) 100.00%
        File name:uYtea.arm.elf
        File size:60'760 bytes
        MD5:2a803a7b7c48b7530c6a53c6dfe718a1
        SHA1:dd3a35733efa7175deda0dba429ed6be44254926
        SHA256:dc9049c50bf6f72a3fb1d6c39f2e3880a05c6f2335b64fd69ef635c541ed2d56
        SHA512:9e7748953d6e93e1924fe24f6f44e67f24f43e801aae0ee6e4419d4ca50435acbfdfd5a0aaa3e8c470c9a47661746d290c721dbb4de803b5f602f1db10d024c8
        SSDEEP:768:lP6aHMzAR6hM2uQBTPpdxnlILKU0vVONyRgGhd2G4NMiplImpcvwJZY10UPZvBqJ:0aHuAzgjjfUKU0NONyRgG+7XtJa10oB
        TLSH:F8533A51B8819613C5D4137BF6BE428D3B2523E8E2DF3217AD222F413BCA82F1D67A45
        File Content Preview:.ELF...a..........(.........4...........4. ...(.....................@...@...............D...D...D...D...0J..........Q.td..................................-...L."....0..........0@-.\P...0....S.0...P@...0... ....R......0...0...........0... ....R..... 0....S

        ELF header

        Class:ELF32
        Data:2's complement, little endian
        Version:1 (current)
        Machine:ARM
        Version Number:0x1
        Type:EXEC (Executable file)
        OS/ABI:ARM - ABI
        ABI Version:0
        Entry Point Address:0x8190
        Flags:0x202
        ELF Header Size:52
        Program Header Offset:52
        Program Header Size:32
        Number of Program Headers:3
        Section Header Offset:60360
        Section Header Size:40
        Number of Section Headers:10
        Header String Table Index:9
        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
        NULL0x00x00x00x00x0000
        .initPROGBITS0x80940x940x180x00x6AX004
        .textPROGBITS0x80b00xb00xc3f00x00x6AX0016
        .finiPROGBITS0x144a00xc4a00x140x00x6AX004
        .rodataPROGBITS0x144b40xc4b40x1f8c0x00x2A004
        .ctorsPROGBITS0x1e4440xe4440x80x00x3WA004
        .dtorsPROGBITS0x1e44c0xe44c0x80x00x3WA004
        .dataPROGBITS0x1e4580xe4580x7300x00x3WA004
        .bssNOBITS0x1eb880xeb880x42ec0x00x3WA004
        .shstrtabSTRTAB0x00xeb880x3e0x00x0001
        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
        LOAD0x00x80000x80000xe4400xe4406.17800x5R E0x8000.init .text .fini .rodata
        LOAD0xe4440x1e4440x1e4440x7440x4a304.31240x6RW 0x8000.ctors .dtors .data .bss
        GNU_STACK0x00x00x00x00x00.00000x7RWE0x4
        TimestampSource PortDest PortSource IPDest IP
        Jan 8, 2025 17:06:52.207103968 CET356541302192.168.2.15141.98.10.115
        Jan 8, 2025 17:06:52.211961031 CET130235654141.98.10.115192.168.2.15
        Jan 8, 2025 17:06:52.212040901 CET356541302192.168.2.15141.98.10.115
        Jan 8, 2025 17:06:52.213092089 CET356541302192.168.2.15141.98.10.115
        Jan 8, 2025 17:06:52.217916965 CET130235654141.98.10.115192.168.2.15
        Jan 8, 2025 17:06:52.217978001 CET356541302192.168.2.15141.98.10.115
        Jan 8, 2025 17:06:52.222762108 CET130235654141.98.10.115192.168.2.15
        Jan 8, 2025 17:06:53.946842909 CET130235654141.98.10.115192.168.2.15
        Jan 8, 2025 17:06:53.947139978 CET356541302192.168.2.15141.98.10.115
        Jan 8, 2025 17:06:53.951886892 CET130235654141.98.10.115192.168.2.15
        Jan 8, 2025 17:06:54.949219942 CET356561302192.168.2.15141.98.10.115
        Jan 8, 2025 17:06:54.954022884 CET130235656141.98.10.115192.168.2.15
        Jan 8, 2025 17:06:54.954127073 CET356561302192.168.2.15141.98.10.115
        Jan 8, 2025 17:06:54.954876900 CET356561302192.168.2.15141.98.10.115
        Jan 8, 2025 17:06:54.959655046 CET130235656141.98.10.115192.168.2.15
        Jan 8, 2025 17:06:54.959708929 CET356561302192.168.2.15141.98.10.115
        Jan 8, 2025 17:06:54.964452028 CET130235656141.98.10.115192.168.2.15
        Jan 8, 2025 17:06:56.658013105 CET130235656141.98.10.115192.168.2.15
        Jan 8, 2025 17:06:56.658231020 CET356561302192.168.2.15141.98.10.115
        Jan 8, 2025 17:06:56.663079977 CET130235656141.98.10.115192.168.2.15
        Jan 8, 2025 17:06:57.659729958 CET356581302192.168.2.15141.98.10.115
        Jan 8, 2025 17:06:57.664668083 CET130235658141.98.10.115192.168.2.15
        Jan 8, 2025 17:06:57.664752960 CET356581302192.168.2.15141.98.10.115
        Jan 8, 2025 17:06:57.665507078 CET356581302192.168.2.15141.98.10.115
        Jan 8, 2025 17:06:57.670330048 CET130235658141.98.10.115192.168.2.15
        Jan 8, 2025 17:06:57.670397997 CET356581302192.168.2.15141.98.10.115
        Jan 8, 2025 17:06:57.675194979 CET130235658141.98.10.115192.168.2.15
        Jan 8, 2025 17:06:59.392729044 CET130235658141.98.10.115192.168.2.15
        Jan 8, 2025 17:06:59.392930031 CET356581302192.168.2.15141.98.10.115
        Jan 8, 2025 17:06:59.401746988 CET130235658141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:00.394562960 CET356601302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:00.399398088 CET130235660141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:00.399466038 CET356601302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:00.400171041 CET356601302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:00.404917002 CET130235660141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:00.404963970 CET356601302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:00.409734011 CET130235660141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:02.090531111 CET130235660141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:02.090780020 CET356601302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:02.095586061 CET130235660141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:03.092499971 CET356621302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:03.097471952 CET130235662141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:03.097546101 CET356621302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:03.098350048 CET356621302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:03.103144884 CET130235662141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:03.103190899 CET356621302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:03.108005047 CET130235662141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:04.809798956 CET130235662141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:04.809993982 CET356621302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:04.814807892 CET130235662141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:05.811633110 CET356641302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:05.816418886 CET130235664141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:05.816479921 CET356641302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:05.817095995 CET356641302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:05.821913004 CET130235664141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:05.821958065 CET356641302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:05.826708078 CET130235664141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:07.542948008 CET130235664141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:07.543186903 CET356641302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:07.543205976 CET356641302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:07.547955990 CET130235664141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:08.545000076 CET356661302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:08.549958944 CET130235666141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:08.550019026 CET356661302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:08.550647974 CET356661302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:08.555653095 CET130235666141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:08.555695057 CET356661302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:08.560455084 CET130235666141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:10.261425018 CET130235666141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:10.261583090 CET356661302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:10.266381025 CET130235666141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:11.263160944 CET356681302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:11.267935991 CET130235668141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:11.267987967 CET356681302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:11.268824100 CET356681302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:11.273623943 CET130235668141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:11.273660898 CET356681302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:11.278389931 CET130235668141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:12.963043928 CET130235668141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:12.963331938 CET356681302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:12.968110085 CET130235668141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:13.965507984 CET356701302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:13.970408916 CET130235670141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:13.970523119 CET356701302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:13.971329927 CET356701302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:13.976161003 CET130235670141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:13.976248026 CET356701302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:13.981018066 CET130235670141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:15.666754961 CET130235670141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:15.667009115 CET356701302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:15.667010069 CET356701302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:15.671813965 CET130235670141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:16.668718100 CET356721302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:16.673496008 CET130235672141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:16.673577070 CET356721302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:16.674288988 CET356721302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:16.679048061 CET130235672141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:16.679121971 CET356721302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:16.683852911 CET130235672141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:18.370882988 CET130235672141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:18.371010065 CET356721302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:18.375807047 CET130235672141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:19.372530937 CET356741302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:19.377346039 CET130235674141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:19.377413988 CET356741302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:19.378040075 CET356741302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:19.382846117 CET130235674141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:19.382888079 CET356741302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:19.387689114 CET130235674141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:21.077554941 CET130235674141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:21.077824116 CET356741302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:21.082590103 CET130235674141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:22.079288960 CET356761302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:22.084100008 CET130235676141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:22.084163904 CET356761302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:22.084666014 CET356761302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:22.089430094 CET130235676141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:22.089478970 CET356761302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:22.094321966 CET130235676141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:23.779557943 CET130235676141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:23.779725075 CET356761302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:23.784569979 CET130235676141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:24.781050920 CET356781302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:24.785830975 CET130235678141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:24.785898924 CET356781302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:24.786463022 CET356781302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:24.791217089 CET130235678141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:24.791263103 CET356781302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:24.796029091 CET130235678141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:26.499388933 CET130235678141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:26.499588966 CET356781302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:26.505100012 CET130235678141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:27.501337051 CET356801302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:27.506109953 CET130235680141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:27.506167889 CET356801302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:27.506784916 CET356801302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:27.511509895 CET130235680141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:27.511599064 CET356801302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:27.516334057 CET130235680141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:29.343734026 CET130235680141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:29.344177008 CET356801302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:29.349024057 CET130235680141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:30.345967054 CET356821302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:30.350824118 CET130235682141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:30.350910902 CET356821302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:30.351511002 CET356821302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:30.356250048 CET130235682141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:30.356302023 CET356821302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:30.361057043 CET130235682141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:32.089180946 CET130235682141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:32.089432955 CET356821302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:32.094249010 CET130235682141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:33.091403961 CET356841302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:33.096210003 CET130235684141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:33.096324921 CET356841302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:33.097197056 CET356841302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:33.101953983 CET130235684141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:33.102083921 CET356841302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:33.106834888 CET130235684141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:34.792443991 CET130235684141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:34.792701960 CET356841302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:34.797602892 CET130235684141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:35.794538021 CET356861302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:35.799310923 CET130235686141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:35.799386024 CET356861302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:35.800122976 CET356861302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:35.804851055 CET130235686141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:35.804920912 CET356861302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:35.809664011 CET130235686141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:37.479618073 CET130235686141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:37.479814053 CET356861302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:37.484621048 CET130235686141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:38.481497049 CET356881302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:38.486459017 CET130235688141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:38.486576080 CET356881302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:38.487504005 CET356881302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:38.492374897 CET130235688141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:38.492429972 CET356881302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:38.497584105 CET130235688141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:40.203061104 CET130235688141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:40.203366995 CET356881302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:40.208136082 CET130235688141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:41.205410004 CET356901302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:41.210184097 CET130235690141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:41.210303068 CET356901302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:41.211360931 CET356901302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:41.216159105 CET130235690141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:41.216226101 CET356901302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:41.220992088 CET130235690141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:42.905154943 CET130235690141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:42.905505896 CET356901302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:42.910269022 CET130235690141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:43.907944918 CET356921302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:43.912769079 CET130235692141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:43.912867069 CET356921302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:43.913800955 CET356921302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:43.918524027 CET130235692141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:43.918579102 CET356921302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:43.923304081 CET130235692141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:45.640125036 CET130235692141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:45.640261889 CET356921302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:45.645066023 CET130235692141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:46.642543077 CET356941302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:46.647357941 CET130235694141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:46.647452116 CET356941302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:46.648464918 CET356941302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:46.653249979 CET130235694141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:46.653307915 CET356941302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:46.658102036 CET130235694141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:48.354923010 CET130235694141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:48.355155945 CET356941302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:48.359971046 CET130235694141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:49.357069016 CET356961302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:49.361849070 CET130235696141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:49.361938000 CET356961302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:49.362586021 CET356961302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:49.367330074 CET130235696141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:49.367393017 CET356961302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:49.372137070 CET130235696141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:51.061919928 CET130235696141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:51.062269926 CET356961302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:51.067032099 CET130235696141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:52.064116955 CET356981302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:52.068962097 CET130235698141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:52.069026947 CET356981302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:52.069909096 CET356981302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:52.074718952 CET130235698141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:52.074764013 CET356981302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:52.079555988 CET130235698141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:53.762141943 CET130235698141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:53.762506008 CET356981302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:53.767309904 CET130235698141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:54.764712095 CET357001302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:54.769604921 CET130235700141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:54.769730091 CET357001302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:54.771238089 CET357001302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:54.776036024 CET130235700141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:54.776108027 CET357001302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:54.780849934 CET130235700141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:56.464389086 CET130235700141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:56.464597940 CET357001302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:56.469449043 CET130235700141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:57.466263056 CET357021302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:57.471085072 CET130235702141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:57.471162081 CET357021302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:57.471959114 CET357021302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:57.476778030 CET130235702141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:57.476836920 CET357021302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:57.481601000 CET130235702141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:59.170500994 CET130235702141.98.10.115192.168.2.15
        Jan 8, 2025 17:07:59.170648098 CET357021302192.168.2.15141.98.10.115
        Jan 8, 2025 17:07:59.175406933 CET130235702141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:00.172189951 CET357041302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:00.176970005 CET130235704141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:00.177037954 CET357041302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:00.177617073 CET357041302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:00.182347059 CET130235704141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:00.182394028 CET357041302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:00.187191010 CET130235704141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:01.870904922 CET130235704141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:01.871203899 CET357041302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:01.875978947 CET130235704141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:02.872541904 CET357061302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:02.877366066 CET130235706141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:02.877425909 CET357061302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:02.877954006 CET357061302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:02.882704973 CET130235706141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:02.882749081 CET357061302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:02.887554884 CET130235706141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:04.594230890 CET130235706141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:04.594372988 CET357061302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:04.599157095 CET130235706141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:05.595715046 CET357081302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:05.600708961 CET130235708141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:05.600765944 CET357081302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:05.601339102 CET357081302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:05.606204033 CET130235708141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:05.606249094 CET357081302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:05.611145973 CET130235708141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:07.296499014 CET130235708141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:07.296634912 CET357081302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:07.301445961 CET130235708141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:08.298015118 CET357101302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:08.302833080 CET130235710141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:08.302902937 CET357101302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:08.303523064 CET357101302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:08.308317900 CET130235710141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:08.308367014 CET357101302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:08.313102961 CET130235710141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:10.000720024 CET130235710141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:10.000874996 CET357101302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:10.005640984 CET130235710141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:11.002573967 CET357121302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:11.007714033 CET130235712141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:11.007790089 CET357121302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:11.008749962 CET357121302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:11.013525009 CET130235712141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:11.013571978 CET357121302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:11.018357992 CET130235712141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:12.731308937 CET130235712141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:12.731679916 CET357121302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:12.736465931 CET130235712141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:13.733537912 CET357141302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:13.738394022 CET130235714141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:13.738507032 CET357141302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:13.739301920 CET357141302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:13.744054079 CET130235714141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:13.744101048 CET357141302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:13.748845100 CET130235714141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:15.434643984 CET130235714141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:15.434824944 CET357141302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:15.439574003 CET130235714141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:16.436340094 CET357161302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:16.441219091 CET130235716141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:16.441287041 CET357161302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:16.441987038 CET357161302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:16.446813107 CET130235716141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:16.446866035 CET357161302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:16.451611042 CET130235716141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:18.140953064 CET130235716141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:18.141099930 CET357161302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:18.148525953 CET130235716141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:19.142509937 CET357181302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:19.147355080 CET130235718141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:19.147422075 CET357181302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:19.147973061 CET357181302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:19.152738094 CET130235718141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:19.152787924 CET357181302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:19.157514095 CET130235718141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:20.874100924 CET130235718141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:20.874202013 CET357181302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:20.879034996 CET130235718141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:21.875801086 CET357201302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:21.880615950 CET130235720141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:21.880682945 CET357201302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:21.881243944 CET357201302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:21.886023998 CET130235720141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:21.886073112 CET357201302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:21.890774965 CET130235720141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:23.589670897 CET130235720141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:23.589864969 CET357201302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:23.594669104 CET130235720141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:24.591514111 CET357221302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:24.596539974 CET130235722141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:24.596633911 CET357221302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:24.597332954 CET357221302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:24.602106094 CET130235722141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:24.602169037 CET357221302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:24.606914997 CET130235722141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:26.278531075 CET130235722141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:26.278745890 CET357221302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:26.283509970 CET130235722141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:27.280278921 CET357241302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:27.285121918 CET130235724141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:27.285191059 CET357241302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:27.285849094 CET357241302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:27.290604115 CET130235724141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:27.290648937 CET357241302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:27.295402050 CET130235724141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:28.997159004 CET130235724141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:28.997400045 CET357241302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:29.002201080 CET130235724141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:29.999500990 CET357261302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:30.004899025 CET130235726141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:30.004981995 CET357261302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:30.005721092 CET357261302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:30.010539055 CET130235726141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:30.010586023 CET357261302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:30.015325069 CET130235726141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:31.717572927 CET130235726141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:31.717837095 CET357261302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:31.722647905 CET130235726141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:32.719299078 CET357281302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:32.724108934 CET130235728141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:32.724194050 CET357281302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:32.724936962 CET357281302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:32.729784012 CET130235728141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:32.729857922 CET357281302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:32.734622002 CET130235728141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:34.420887947 CET130235728141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:34.421051025 CET357281302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:34.425839901 CET130235728141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:35.422763109 CET357301302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:35.427556992 CET130235730141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:35.427613974 CET357301302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:35.428534985 CET357301302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:35.433295965 CET130235730141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:35.433343887 CET357301302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:35.438141108 CET130235730141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:37.131916046 CET130235730141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:37.132370949 CET357301302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:37.137187958 CET130235730141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:38.134560108 CET357321302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:38.139417887 CET130235732141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:38.139514923 CET357321302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:38.140530109 CET357321302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:38.145261049 CET130235732141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:38.145306110 CET357321302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:38.150063992 CET130235732141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:39.904963017 CET130235732141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:39.905244112 CET357321302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:39.910046101 CET130235732141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:40.907417059 CET357341302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:40.912269115 CET130235734141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:40.912363052 CET357341302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:40.913336039 CET357341302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:40.918081045 CET130235734141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:40.918140888 CET357341302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:40.922916889 CET130235734141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:42.732475042 CET130235734141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:42.732695103 CET357341302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:42.737544060 CET130235734141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:43.734437943 CET357361302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:43.739749908 CET130235736141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:43.739820004 CET357361302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:43.740387917 CET357361302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:43.745559931 CET130235736141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:43.745606899 CET357361302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:43.751121044 CET130235736141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:45.573111057 CET130235736141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:45.573431969 CET357361302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:45.578257084 CET130235736141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:46.575083017 CET357381302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:46.579885960 CET130235738141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:46.579977989 CET357381302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:46.580765963 CET357381302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:46.585668087 CET130235738141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:46.585717916 CET357381302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:46.590538025 CET130235738141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:48.281096935 CET130235738141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:48.281441927 CET357381302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:48.286189079 CET130235738141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:49.282872915 CET357401302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:49.287646055 CET130235740141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:49.287705898 CET357401302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:49.288350105 CET357401302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:49.293078899 CET130235740141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:49.293123007 CET357401302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:49.297899008 CET130235740141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:51.013292074 CET130235740141.98.10.115192.168.2.15
        Jan 8, 2025 17:08:51.013420105 CET357401302192.168.2.15141.98.10.115
        Jan 8, 2025 17:08:51.018179893 CET130235740141.98.10.115192.168.2.15

        System Behavior

        Start time (UTC):16:06:45
        Start date (UTC):08/01/2025
        Path:/tmp/uYtea.arm.elf
        Arguments:/tmp/uYtea.arm.elf
        File size:4956856 bytes
        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

        Start time (UTC):16:06:45
        Start date (UTC):08/01/2025
        Path:/tmp/uYtea.arm.elf
        Arguments:-
        File size:4956856 bytes
        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1

        Start time (UTC):16:06:45
        Start date (UTC):08/01/2025
        Path:/tmp/uYtea.arm.elf
        Arguments:-
        File size:4956856 bytes
        MD5 hash:5ebfcae4fe2471fcc5695c2394773ff1